The DPDP Act, 2023 — in one everyday example
No legal terms to start with. Four everyday situations, and everything the law changes about each one.
This is just one illustration — the same law plays out the same way across sectors. Pick another everyday example:
Forget the Act for a second. Here are the two people this law is actually about — you've been both, depending on the day.
Ramesh
A patient booking a blood test. His data. His say in what happens to it.
ABCD Diagnostics
The lab collecting Ramesh's data. Now legally responsible for it.
Ramesh and ABCD Diagnostics are fictional, used only to illustrate how the Act works. Any resemblance to a real person or business is coincidental and unintended.
Here's what the law actually requires, step by step:
Before taking his sample, the lab must clearly tell Ramesh what it's collecting (name, phone, test results) and exactly why — not buried in fine print, in plain language he can actually read.
Ramesh gives his Consent — a real yes, not a pre-ticked box he scrolled past. He could just as easily have said no to any part he wasn't comfortable with.
The lab can use Ramesh's data to run the test and share the report — nothing more. It can't quietly sell his phone number to a pharmacy or a health insurance marketer without asking him separately.
A blood test report is high-risk data — so the lab can't just email it as an open attachment. It should send it password-protected, because that's what "reasonable" security looks like for something this sensitive. And if its systems are ever hacked and data leaks anyway, it must tell both Ramesh and the government's Data Protection Board — quickly, not months later.
Months later, Ramesh can ask the lab what it still holds on him, get a wrong entry corrected, or ask it to delete his data once he no longer needs their service.
If the lab ignores any of this, Ramesh can complain — first to the lab, then to the Data Protection Board, which can fine the lab up to ₹250 crore for serious violations.
That's the whole law, really — one relationship, two sides, six moments. Here's what to remember depending on which side you're on:
Ramesh's checklist
- You can say no, or say yes only to part of it.
- You can ask what's held about you, anytime.
- You can get it corrected or deleted.
- You have somewhere to complain if ignored.
ABCD's checklist
- Ask plainly, before you collect.
- Use data only for what you asked permission for.
- Protect it, and report leaks fast.
- Be ready to show, correct, or erase on request.
Eight words, if you need them
- Data Principal
- The person the data belongs to — Ramesh, Sunita, Arjun, or Kavya, in these stories.
- Data Fiduciary
- The organisation deciding why and how the data is used — the lab, the NBFC, the school, the agency.
- Data Processor
- A vendor handling data on a Fiduciary's behalf, like a credit bureau — bound by contract to protect it the same way.
- Consent
- A clear, specific yes — never assumed, never buried in fine print.
- Verifiable Parental Consent
- For a child's data, the Act requires a parent or guardian to consent on their behalf, in a way the Fiduciary can verify.
- Cross-Border Transfer
- Sending personal data outside India — generally allowed, except to countries the government specifically restricts.
- Data Protection Board
- The government body a Data Principal can complain to, and which can fine a Fiduciary.
- Data Breach
- Any leak, loss, or unauthorised access to personal data that the Fiduciary must report.
